Назад
Company hidden
2 дня назад

Senior Risk Management / GRC Manager (Fintech)

Формат работы
remote (только Netherlands)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Netherlands
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Risk Management / GRC Manager (Fintech): Developing and maintaining security, governance, risk management, and compliance programs for financial infrastructure with an accent on DORA compliance, IT security controls, and regulatory frameworks. Focus on conducting technical risk assessments, managing security incidents, coordinating audits, and reporting control effectiveness to senior management and the board.

Location: Remote, candidates must be based in the Netherlands

Company

hirify.global provides API- and SDK-based financial infrastructure for moving and transferring fiat, crypto, and stablecoins, together with a global regulatory stack.

What you will do

  • Own and manage compliance with the Digital Operational Resilience Act (DORA) and other IT security regulations.
  • Develop and maintain governance frameworks, technical policies, procedures, and security controls.
  • Manage compliance programs aligned with ISO 27001, SOC 1, SOC 2, GDPR, and NYDFS Part 500.
  • Conduct security assessments, vulnerability scans, penetration tests, technical risk assessments, and control effectiveness reviews.
  • Oversee technical incident management, forensic investigations, root cause analysis, and corrective actions.
  • Collaborate with auditors, regulators, security teams, technical stakeholders, senior management, and the board.

Requirements

  • Prior experience in a Risk Management or GRC leadership role.
  • Prior experience with DORA is required.
  • Proven experience in technical IT security, governance, risk management, and compliance.
  • Strong knowledge of IT governance frameworks, regulatory requirements, risk assessment methodologies, and GRC tools.
  • Experience with IT audit processes and procedures, plus strong analytical, communication, and problem-solving skills.
  • Ability to manage multiple technical projects and priorities in a fast-paced environment.

Nice to have

  • CISSP, CISM, CRISC, or CISA certification.
  • Experience with SOC 1, SOC 2, and ISO 27001.
  • Knowledge of GDPR, NYDFS Part 500, and other relevant regulations.

Culture & Benefits

  • Opportunity to earn equity.
  • Maternity and paternity leave.
  • WeWork membership.
  • Yearly work-from-home stipend.
  • Learning and development stipend after six months.
  • Culture emphasizing ownership, collaboration, initiative, empathy, adaptability, transparency, and integrity.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →